|
247281
|
9.8 |
CRITICAL
Network
|
a10networks
|
acos_web_application_firewall
|
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL inj…
|
CWE-89
SQL Injection
|
CVE-2018-15904
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247282
|
8.8 |
HIGH
Network
|
asus
|
dsl-n12e_c1_firmware
|
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, s…
|
CWE-78
OS Command
|
CVE-2018-15887
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247283
|
7.5 |
HIGH
Network
|
visiology
|
flipbox
|
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
|
CWE-22
Path Traversal
|
CVE-2018-15810
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247284
|
6.1 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configura…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15699
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247285
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15698
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247286
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
|
CWE-200
Information Exposure
|
CVE-2018-15697
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247287
|
4.3 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15696
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247288
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
|
CWE-22
Path Traversal
|
CVE-2018-15695
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247289
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code executio…
|
CWE-22
Path Traversal
|
CVE-2018-15694
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247290
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15899
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|